Key takeaways
- Mullvad will stop offering its public DNS resolver service.
- The company will support Quad9, another privacy-focused DNS provider.
- People using Mullvad’s public DNS addresses need to choose a replacement.
- Mullvad VPN customers can still use the VPN app’s DNS protection.
Mullvad encrypted DNS is ending as a public service, and Mullvad plans to support Quad9 instead. Mullvad encrypted DNS means a tool that hides DNS lookups from people watching a network. The move affects people who entered Mullvad’s DNS addresses in their phone, browser, or router. It does not mean the Mullvad VPN app is shutting down.
DNS is often called the internet’s phone book. It turns a name such as a website address into the number a device needs. Without privacy tools, a network provider may see many of those lookups. That can reveal the sites a person tries to visit.
Why is Mullvad encrypted DNS being switched off?
Mullvad says it will retire its public resolver and sponsor Quad9. A DNS resolver is the server that finds the internet address behind a web name. The firm’s choice puts its support behind a separate service rather than running two similar public systems.
The news matters because public DNS is easy to set and forget. A person may have placed a resolver address in a home router years ago. Then every device on that Wi-Fi network may use it. Those users should check their settings before the service ends.
Mullvad has built its name around privacy tools, including its paid VPN. A VPN creates an encrypted path between a device and a VPN server. Its public DNS option offered a free way for people to protect lookups, even without buying a VPN.
Quad9 is a nonprofit resolver service that uses the memorable address 9.9.9.9. It says it blocks many known harmful domains while aiming to protect user privacy. A harmful domain can lead to scams, malware, or fake login pages.
What will change for current users?
People who only use the Mullvad VPN app should not confuse this news with a VPN shutdown. The app handles DNS requests inside its protected connection. Still, users should read Mullvad’s notices and update the app when asked.
The bigger change is for people who manually chose Mullvad encrypted DNS outside the app. Mullvad’s public resolver has used addresses including 194.242.2.2. Some versions also offered filters for ads, trackers, and adult content.
Once a device can no longer reach its chosen resolver, websites may fail to load. That sounds scary, but the fix is usually simple. Pick another trusted DNS service and replace the old addresses in your device or router settings.
Do not rush to copy an address from a social post. Use the provider’s own setup page, because a single wrong digit can send requests elsewhere. Quad9 publishes its options on its official website.
How do DNS choices compare after the change?
| Option | What it does | Who may need action |
|---|---|---|
| Mullvad VPN app | Protects traffic and DNS inside a VPN connection | Most app users should check official updates |
| Mullvad public DNS | Public resolver that Mullvad is retiring | Anyone who set its address manually |
| Quad9 | Public resolver with threat-blocking options | People seeking a replacement |
A router change can cover a whole home. For example, one update may affect a laptop, game console, smart TV, and tablet. But a router setting also affects guests, so families should choose carefully.
Encrypted DNS comes in two common forms: DNS over HTTPS and DNS over TLS. Both wrap DNS lookups in encryption. They stop many local network observers from reading the lookup, but they do not make every part of internet use private.
That difference is easy to miss. Your browser, websites, and apps can still collect data in other ways. A private DNS provider is useful, but it is not a magic invisibility cloak.
Why is Quad9 a notable choice?
Quad9 has a clear public purpose: it offers DNS protection without asking people to pay for a subscription. It also uses threat feeds to block many risky destinations. A threat feed is a list of web addresses linked to known danger.
Its 9.9.9.9 address is far easier to remember than most DNS numbers. That helps people enter it on devices with clumsy menus. Yet ease of use should not replace checking the provider’s privacy policy and setup guide.
The move also shows how hard free privacy services are to maintain. Servers cost money, and secure systems need skilled staff. By sponsoring Quad9, Mullvad can support a public option while focusing its own work on its VPN service.
This change comes as more people question who sees their online activity. It also follows wider concern about browser privacy and web security. For a related look at browser risk, read our report on Chrome security flaw fixes.
What should users do next?
First, find out whether you use Mullvad encrypted DNS manually. Check DNS settings in your phone, computer, browser, and router. If you only use Mullvad through its VPN app, look at the app’s official support messages instead.
Next, choose a provider based on what you need. Some people want encryption. Others want scam blocking, family filters, or fewer ads. Read the provider’s own instructions, including Mullvad’s DNS over HTTPS and TLS guide, before changing anything.
Here is the simple answer: Mullvad encrypted DNS is being retired for public users, so manual users should move to another trusted resolver such as Quad9. The VPN service remains separate. Save your old settings first, then test a few websites after making the change.
FAQs
What is encrypted DNS?
Encrypted DNS hides the request that asks where a website is located. It can protect that request from people on the same Wi-Fi network. It does not hide everything else you do online.
How can I tell if I use Mullvad’s public DNS?
Look in your device or router network settings for DNS addresses. If you see 194.242.2.2 or another Mullvad address, you likely need a replacement. The Mullvad VPN app is a separate case.
Why is Quad9 being supported?
Mullvad is backing Quad9 after ending its own public resolver. Quad9 offers encrypted DNS options and security blocking. Its well-known public address is 9.9.9.9.
Mullvad encrypted DNS: the shutdown boundary
Mullvad says its public encrypted DNS endpoints will stop operating on November 2, 2026. The company is redirecting support to the nonprofit Quad9 resolver rather than maintaining a parallel public service. Mullvad’s default browser setup is expected to migrate automatically, but people who manually entered a Mullvad DNS-over-HTTPS address must change their settings.
Mullvad encrypted DNS is ending only as a public resolver service; DNS used inside the Mullvad VPN remains available. That boundary prevents a common misunderstanding. VPN customers do not need to abandon the VPN because of the announcement, while non-VPN users and custom-profile users do need to review their configurations.
Downloaded iOS and macOS profiles are particularly important because a profile can keep pointing at a retired hostname after a browser setting has changed. Organizations should inventory managed-device policies, router settings and operating-system secure-DNS templates rather than assuming the migration is universal.
What changes when users move to Quad9
Encrypted DNS protects the lookup between a device and its resolver from simple network observation. It does not make browsing anonymous, hide destination IP addresses or replace a VPN. The selected resolver can still influence logging, retention, blocking and legal-jurisdiction choices.
Quad9 is a Swiss-based nonprofit that offers encrypted DNS and blocks domains associated with known threats on its standard service. Users who want a different filtering policy should compare resolver documentation rather than copying an address from an unverified guide. The correct endpoint also depends on whether the device supports DNS over HTTPS or DNS over TLS.
Before switching, users should save the existing configuration, follow the resolver’s official instructions, restart the network connection and test that encrypted DNS is active. Managed fleets should stage the policy change on a small group first so captive portals, split DNS and internal domains keep working.
Why Mullvad is consolidating support
Operating a global public resolver requires servers, abuse handling, monitoring and continuous security work. Sponsoring an established nonprofit can concentrate funding on shared privacy infrastructure instead of duplicating it. The announcement does not disclose every financial or operational term, so claims about savings or capacity should remain bounded.
The move fits a broader debate over concentrating internet infrastructure among a small number of providers. Supporting Quad9 adds resources to an independent option, but users still need diversity and clear exit paths. A configuration that can be changed without replacing an entire security stack is more resilient.
For adjacent security context, read the Chrome zero-day response, Cisco IOS XR flaw guidance, Microsoft Teams helpdesk attacks and the C-Track breach analysis.
Sources and verification
- Mullvad announcement
- Quad9 official documentation
- TechRadar reporting
- Technobezz reporting
- IETF DNS-over-HTTPS standard
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.



